CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15114  CVE-2005-3910  Candidate  merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.  Assigned (20051130)  None (candidate not yet proposed)    View
80650  CVE-2015-3373  Candidate  The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.  Assigned (20150421)  None (candidate not yet proposed)    View
15370  CVE-2005-4166  Candidate  Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.  Assigned (20051211)  None (candidate not yet proposed)    View
80906  CVE-2015-3629  Candidate  Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.  Assigned (20150501)  None (candidate not yet proposed)    View
15626  CVE-2005-4422  Candidate  Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.  Assigned (20051220)  None (candidate not yet proposed)    View

Page 829 of 20943, showing 5 records out of 104715 total, starting on record 4141, ending on 4145

Actions